nyahahahaaaa..
I only share the css linker that I made here in the first page..
I hope it can help many members here..
But for the JS Linker ( all browser compatible )..I'll never share it to public..
Coz all I want is to embed mp3 and youtube in my comments.
[b]@feruzz.[/b] I'll try my best not to share the linker to anyone unknown.
Last edited by xavierkym (2008-06-06 05:07:28)
nyahahahaaaa..
I only share the css linker that I made here in the first page..
I hope it can help many members here..
But for the JS Linker ( all browser compatible )..I'll never share it to public..
view source, copy, paste on notepad, send it.
great
view source, copy, paste on notepad, send it.
great
Hello lae kher..
how r u??
I never use ur codes..
ur friend begs me to see ur codes..
I think he wants to try me..

btw..
FERUZZ!!!!! where are you???
i'v found someone inject this on his comment page:
<">and it works w/o using your quick testimonials 







i think we cant use this type of injection anymore
nyahahahahaaaa..
We usually have a joke Lae Kher..
Please smile..
Btw,how r u??
I miss chatting with u in YM..
guys...
pls take note that the cradle linker already has been filtered by Filster..
so please guys do not share to everyone about my method even to your best friend
just let them find the new hole
[/quote]
No worries bro.
[quote=KhErMiNaToR]^ he can see my codes, im not use encryption anymore 
btw..
FERUZZ!!!!! where are you???
i'v found someone inject this on his comment page:
Code:
<">and it works w/o using your quick testimonials 







i think we cant use this type of injection anymore
[/quote]
WTF
waaa. I though it was already filtered.
but then it isn't wakoko.
Nice discovery.
waaa. I though it was already filtered.
but then it isn't wakoko.
Nice discovery.
[/quote]
LOL you laughing
what if i injecting this?
[quote]for (var i=0;i<100000000000000000;i++) {
alert("wakokokoko!!");
}[/quote]
on your comments

btw..
FERUZZ!!!!! where are you???
i'v found someone inject this on his comment page:
Code:
<script src='URL JS'></script>
and it works w/o using your quick testimonials 







i think we cant use this type of injection anymore
[/quote]
hahaha....
nice discovery
I've saw one member in FT Malaysia can access the Backstage (I guess)
he has showed to me the link of this thread
his name is CraZyRowkZ Emo
thats why he know how to inject the script in the comment
but i erase that already,
coz im affraid someone (i mean another person) doing the same thing
i think if a normal member click this link, he/he can access the backstage..
http://theftalk.com/f34-The-Backstage.html
just wondering
[url]http://theftalk.com/p1143909-Yesterday-15%3A51%3A10.html#p1143909[/url]
I didnt tell him how to inject the script
this is not a joke...
pls take seriously
Last edited by feruzz (2008-06-06 13:01:08)
just paste them into textarea then click submit button
Last edited by feruzz (2008-06-06 13:38:00)
i think fs team was concentrate to media box.
they forget there are to many box on their site
and testimonials text area is one of 'em
about CraZyRowkZ Emo aka elyas
dont worry because he also will keep secret about XSS
[quote=KhErMiNaToR]LOL you laughing
what if i injecting this?
for (var i=0;i<100000000000000000;i++) {
alert("wakokokoko!!");
}
on your comments[/quote]
yes you can...
just insert
<">the <script> hasnt been filtered LOL
Last edited by feruzz (2008-06-07 00:05:47)

on my test page
but only 3 alert,,
I've already injected to eykalsyamim's page before & he doesnt know anything...
only viewers can see the alert
Last edited by feruzz (2008-06-07 06:00:50)